CVE-2026-100869
8.2
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Summary
Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing customers to trigger refunds on completed orders. Attackers with order tokens can submit arbitrary payment actions like refunds that payment gateways execute while Sylius maintains order as paid, causing financial loss.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Sylius | Sylius | 2.0.0 < 2.1.16 | affected |
| Sylius | Sylius | 2.2.0 < 2.2.9 | affected |
Weaknesses
- CWE-863: Incorrect Authorization
References
- https://github.com/Sylius/Sylius/security/advisories/GHSA-2rv4-pjmm-7fxf
- https://github.com/Sylius/Sylius/pull/19214
- https://github.com/Sylius/Sylius/commit/5813831f60f3a60b735a86a57c4b519626a3b75d
- https://github.com/Sylius/Sylius/releases/tag/v2.2.9
- https://github.com/Sylius/Sylius
- https://www.vulncheck.com/advisories/sylius-2-x-before-2.1.16-and-2.2.9-arbitrary-payment-action-via-shop-api
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.